Mintlify: AI-powered platform for generating and hosting software documentation.
3+ YOE3+ years GRC/compliance program management with direct audit ownership, hands-on Drata (or Vanta) administration, vendor and auditor management, strong follow-through and automation bias.
Entegrata: Provides an Azure-based data lakehouse platform for law firms.
Hands-on Azure cloud security, Entra ID and EDR experience, detection engineering with KQL, SOC 2/Drata compliance ownership, and ability to run security reviews and incident response.
Azure, Defender for Cloud, KQL, Log Analytics, Azure Monitor, Event Hub, incident.io, Entra ID, SentinelOne, Microsoft Defender, Sophos, Microsoft Intune, Drata, Pulumi, Bicep, GitHub Actions, AKS, Container Apps, Azure SQL, Databricks, Data Factory, Key Vault, PowerShell, Bash, Go, Azure SDK
First AdvantageNASDAQ: FA: Provides employment background screening and digital identity verification services.
1+ YOE1+ years compliance/risk experience; familiarity with SOX, SOC 2, ISO 27001, NIST; experience with Trust Center platforms (Drata, Vanta) and control automation; strong communication and analytical skills.
Berlin or Iași or London or New York City or São Paulo
HybridFull Time
Taktile: Platform for automated financial risk and credit decisioning.
4+ YOE4+ years GRC or security compliance at a SaaS company; owned SOC 2 program; Vanta/Drata/Secureframe experience; hands-on scripting against AWS for automated evidence; strong written communication.
Substack: Platform for independent writers to publish and monetize newsletters.
3+ YOE3–5 years in corporate IT/systems administration; hands-on Okta and Apple-focused MDM experience (Iru/Kandji/Jamf); familiarity with SOC 2 and compliance platforms (Vanta/Drata); strong communication and documentation skills.
RISCPoint: Provides cybersecurity compliance, cloud security, and risk management advisory.
3+ YOE3+ years supporting or leading cybersecurity compliance engagements; experience with SOC 1/2, ISO 27001, HITRUST, HIPAA; familiarity with Vanta/Drata and cloud platforms; bachelor’s or master’s degree preferred; industry certifications preferred.
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
Silver Spring, Maryland, United States
HybridFull Time
For Your Information, Inc.: Provides HR and IT services to federal government agencies.
8+ YOE8+ years in cybersecurity/GRC/IT audit with direct SOC 2 Type 2 audit experience, GRC platform experience (Drata preferred), SaaS/cloud expertise, evidence review, strong written communication, and stakeholder coordination skills.
Velera: Integrated fintech and payment processing solutions for credit unions.
8+ YOE8+ years in cyber GRC or related fields, 5+ years in GRC program management, experience implementing GRC tools (Optro,Vanta,Drata,OneTrust), PCI/NIST/SOC audit experience, strong stakeholder and program skills.
Austin or Denver or Indianapolis or Los Angeles or San Francisco or New York or Salt Lake City or Minneapolis or Seattle or Nashville
$135k-$150k/yrRemoteFull Time
Givebutter: Fundraising and CRM platform for nonprofit organizations.
5+ YOE5+ years IT experience; hands-on IT ops (MDM, device and SaaS administration, identity lifecycle), Notion administration, GRC project management with Vanta/Drata, familiarity with SOC 2/ISO 27001/PCI, remote/Mac environment experience.
Vanta, Drata, Notion, Google Workspace, Slack, 1Password, Mobile Device Management (MDM), Claude, Cursor, ChatGPT
Clear Capital: AI-driven real estate valuation and property data solutions.
3+ YOE5+ years GRC/risk/compliance experience with Bachelor’s (or 3+ years with Master’s) or equivalent; deep knowledge of NIST, ISO, SOC 2, GLBA/CCPA/GDPR; relevant certifications (CISSP, CISM, CISA, CRISC, AIGP); familiarity with Vanta, Drata, OneTrust, cloud and DevOps; strong analytics and communication.
NIST CSF, NIST RMF, ISO 27001, ISO 27002, ISO 42001, SOC 2, GLBA, CCPA, GDPR, Vanta, Drata, OneTrust, DevOps, cloud computing
Sr. Security Engineer, Corporate Information Security
New York City, New York, United States
$165k-$185k/yrHybridFull Time
Betterment: Automated investment management and retirement planning platform.
6+ YOE6+ years security engineering experience with deep IAM expertise; strong knowledge of authentication protocols, endpoint hardening, vulnerability management, automation (Python/Go), and SOC 2/ISO 27001 compliance.
Lantern: Connects employees to high-quality surgical, cancer, and infusion care.
5+ YOE5+ years GRC/compliance/InfoSec; 3+ years healthcare/healthtech; degree in information security, CS, or related; experience with risk registers, HITRUST/SOC 2, HIPAA, NIST CSF, AI RMF; GRC tools.
Pomelo Care: Virtual healthcare provider for mothers, infants, and women.
7+ YOE2+ Mgmt7+ years in IT support/operations with 2+ years managing teams; hands-on experience with Okta, Google Workspace, Slack, Iru or Jamf; HIPAA and SOC 2/HITRUST familiarity; strong communication and customer service skills.
Okta, Google Workspace, Slack, Iru (formerly Kandji), Jamf, Vanta, Drata
Temporal Technologies: Durable execution platform for building resilient, scalable cloud applications.
8+ YOE8+ years in GRC or info security compliance, hands-on experience with major frameworks (SOC2, ISO 27001, HIPAA, PCI-DSS, FedRAMP), managing high volumes of security questionnaires (SIG, CAIQ), scripting/automation (Python, Bash), strong customer-facing and risk assessment skills.
BARR Advisory: Performs cybersecurity audits and risk management consulting services.
3+ YOEBachelor's or equivalent; 3+ years IT audit/cybersecurity compliance experience; 2+ years leading SOC 1/SOC 2 engagements; knowledge of AICPA TSC; cloud experience (AWS/Azure/GCP); strong communication and mentoring; able to obtain industry certification within one year.
AWS, Azure, Google Cloud Platform, Vanta, Drata, Secureframe
UP.Labs: Builds and scales mobility-focused startups with corporate partners.
7+ YOE7+ years in security engineering/DevSecOps with hands-on control implementation, SOC 2 readiness experience, compliance automation platform operation, identity/cloud/SDLC controls implementation, and familiarity with GitHub, Okta, Google Workspace, Slack, and major cloud providers.
Extensive experience operating SOC 2 and HIPAA controls, cloud and infrastructure-as-code (Terraform), identity and access management, SIEM and incident response, and leading IT/security teams.